A valid request URL is required to generate request examples{
"token": "<string>",
"baseUrl": "<string>",
"padCode": "<string>",
"userId": "<string>",
"resolution": 123
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Open a live video session on a device
Mint the short-lived vendor token a browser needs to drive this device as real-time video, the interactive alternative to polling the screenshot route. Hand the whole body to the video SDK: token is the SDK credential, baseUrl is the endpoint it connects to, padCode is the device’s vendor instance, userId is a stable per-person id for the SDK, and resolution is the SDK’s profile (16 is 720x1920, and the SDK then aligns to the device’s real aspect ratio).
PERSON ONLY. This is a human’s real-time control of a device, so an API key is refused: an agent has nobody behind it to drive as, and it drives through the governed action path instead. The token is a credential, so do not store it; it is never written to a log.
YOU NEED THE SEAT. You may open a session when your organisation holds a lease on the device, whether it is yours, a colleague’s, or a running agent’s, and opening one never seizes the device or interrupts an agent. When your organisation holds no lease there is nothing to drive under, so take the device first with POST /v1/devices/{deviceId}/lease, then open the session. A device that is not a cloud phone has no video channel and answers 400.
Hosted deployments only. A local checkout does not mount this route, so calling it there is a 404.
A valid request URL is required to generate request examples{
"token": "<string>",
"baseUrl": "<string>",
"padCode": "<string>",
"userId": "<string>",
"resolution": 123
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "unauthorized",
"reason": "missing_credentials",
"hint": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}{
"error": {
"code": "payload_too_large",
"message": "<string>"
}
}{
"error": {
"code": "rate_limited",
"message": "<string>"
}
}{
"error": {
"code": "backend_resolution_failed",
"message": "<string>",
"retryable": true
}
}Authorizations
The control surface credential. Send Authorization: Bearer <token>.
Two kinds of token are accepted and they are told apart by shape, not by a separate header. A token beginning pbk_ is an org scoped API key, whose public half and secret half are generated together and of which only a hash of the secret is ever stored; anything else is treated as an OAuth 2.1 access token and verified against the authorization server's keys.
Both resolve to the same context: an org, a principal and a set of scopes. Nothing downstream branches on which channel you used, with one deliberate exception, key management, which requires a signed-in person so that a key can never mint another key.
Scopes are enforced when MCP tools are REGISTERED rather than when they are called, so a tool your credential cannot use is absent from tools/list rather than refused mid gesture.
Path Parameters
The deviceId from a listing.
Response
A live session. Hand the whole body to the browser's video SDK.
A short-lived vendor SDK credential for the media stream. Do not store it.
The RTC endpoint the SDK connects to.
The device's vendor instance code.
A stable, sanitized per-person id for the SDK. It carries no secret.
The SDK resolution profile: 16 selects 720x1920, then the SDK aligns to the real ratio.